Interactive · nothing to fill in · no email required
Most of your AI arrived uninvited. All of it is your responsibility.
Nobody signed off the writing tool in Marketing, the transcription bot sitting on your customer calls, or the AI your vendor switched on in a release note last March. They are running on your data, in your name, today. Answer three questions and see roughly how many there are.
Already have a list? Use yours instead of our assumptions.
—
hover any dot
A model, not a measurement — not based on your organisation and not a Moustr finding.
Distinct AI systems the model expects, across all three routes in
No name against them if an auditor, a customer or the board asks
Built into software you already own. Only the vendor can tell you
Systems you could show a defensible record for today
Two pages: what you entered, what the model produced, what follows if it is roughly right, and every assumption listed so whoever you forward it to can check the arithmetic. No form required.
A ninety-second tour of the product itself — the AI Record, the ownership state against each system, and where the evidence sits. It is a look at the interface rather than a walkthrough of your scenario. No sign-up.
The tour runs on moustr.com itself. Nothing third-party loads.
03 · Off the office network, do you see anything?
Company networks and set-up devices are covered. Personal devices off them, and some
VPN configurations, are outside what we detect. You should hear that from us rather than find it
out later.
05 · Has every system got someone with authority to act?
Ownership without authority is a name in a spreadsheet. Who can act on a system is a
decision for your organisation, not a number this model can produce.
How much of this could you actually answer for?
Every system sits somewhere between "nobody knows it's there" and "we can prove it". The whole job is moving them to the right — and the bar below is what most organisations find when they first look.
Internally we call these five stages the assurance ladder. You don't have to.
These are our numbers. Put yours in instead.
Every figure above comes from twelve assumptions we chose, not from your organisation.
You almost certainly know better than we do. Change any of them and the estate, the dots
and the five stages all recompute as you type.
nothing changed yet — these are all ours
Use my own numbersHide the numbers
These are our numbers. Put yours in instead.
Every figure above comes from twelve assumptions we chose, not from your organisation. You almost certainly know better than we do. Change any of them and the estate, the dots and the five stages all recompute as you type.
nothing changed yet — these are all oursThese are illustrative planning coefficients, not measurements, and not derived from Moustr customer data. They are deliberately conservative. If one looks wrong for your organisation, change it. That is the point: the argument worth having internally is about the numbers, not about whether the problem exists.
The one measured figure on this page is not ours. 42% of organisations confirmed an AI-related incident in the preceding twelve months and 31% reported a near-miss (Netrio / Censuswide, June 2026). Everything else here is modelled.
THE THREE ROUTES IN
Only one of them goes through IT.
The model is a guess. The register isn't.
Everything above is arithmetic on assumptions you can edit. A thirty-day trial replaces it with your actual estate: agentless discovery of what is running, each system classified with human approval, and a named owner recorded against each one. You find out whether the model was pessimistic or generous.
Already have a list from a scanner or a spreadsheet? Check what it can prove.
Agentless by default · read-only · you choose what is included
Moustr does not remediate, block or revoke. It discovers, classifies, assigns ownership and evidences.
Everything you have modelled, in two pages you can forward to whoever asks you the question.
What this tool is, and why the numbers are published
Most organisations cannot answer the question "what AI are we running?" — not through negligence, but because nobody planned the estate. It accumulated. The Sprawl Simulator models what that accumulation probably looks like at your size, using twelve planning assumptions that are printed on this page and editable by anyone who disagrees with them.
Why AI estates are larger than organisations expect
AI enters an organisation three ways, and only one of them passes through IT. Bought AI is licensed, procured and on the books — the smallest group and the best documented. Built-in AI is switched on inside platforms already owned, often by a vendor release note, with no procurement record and no decision anywhere. Picked-up AI is what individuals started using because it was faster than waiting for approval. The last two are ordinary behaviour rather than misconduct, and together they usually make up most of the estate.
Why a network scan cannot find everything
AI enabled inside software you already run does not appear on your network as anything new, so no scanning product of any kind will detect it. Only the vendor can declare it. That is why technical discovery has to be combined with what people tell you and what vendors publish, rather than treated as sufficient on its own — a limitation worth understanding before buying any discovery tool, including ours.
Why an inventory is not the same as evidence
A list of systems tells an auditor almost nothing. A record only counts as evidence if it names an accountable owner, states what the system is for and what data it touches, and can be produced on demand without a fire drill. The gap between what an organisation has listed and what it could actually prove is usually the largest number this model produces, and it is the one that costs most to close under deadline pressure.
What the deadline actually is
The nearest pressure is not in the regulation. Enterprise customers already ask about AI governance in security questionnaires, and ISO/IEC 42001 treats an inventory, assigned accountability and an evidence base as preconditions rather than outcomes. Under the EU AI Act, AI literacy duties (Article 4) have applied since February 2025, and obligations for Annex III high-risk systems apply from 2 December 2027. Building those now is inexpensive; reconstructing them under deadline, from an estate nobody has mapped, is not.
What this model is not
It is not a measurement of your organisation and no Moustr system has observed your estate. It is not derived from customer data. It prices nothing and makes no claim about savings or financial exposure. It is not an assessment of compliance with ISO/IEC 42001 or the EU AI Act and should never be shown to an auditor or a regulator as evidence of anything. The one measured figure referenced anywhere on this page is not ours: 42% of organisations confirmed an AI-related incident in the preceding twelve months and 31% reported a near-miss (Netrio / Censuswide, June 2026).